Impact
The vulnerability is located in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It allows a low‑privileged attacker with network access over HTTP to fully compromise the application, potentially taking complete control and jeopardizing confidentiality, integrity and availability of financial data.
Affected Systems
Oracle Corporation's Hyperion Financial Management product, version 11.2.26.0.000.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity with serious impact on confidentiality, integrity and availability. The EPSS score of less than 1% indicates a low exploitation probability in the general population, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack path is straightforward: the attacker only needs network access to the Hyperion HTTP port and can leverage a low‑privileged user account to hijack the system. Successful exploitation can lead to full takeover and compromise of all controlled financial information.
OpenCVE Enrichment